Title: Bithead's Replies | WordPress.org

---

# Bithead

  [  ](https://wordpress.org/support/users/bithead/)

 *   [Profile](https://wordpress.org/support/users/bithead/)
 *   [Topics Started](https://wordpress.org/support/users/bithead/topics/)
 *   [Replies Created](https://wordpress.org/support/users/bithead/replies/)
 *   [Reviews Written](https://wordpress.org/support/users/bithead/reviews/)
 *   [Topics Replied To](https://wordpress.org/support/users/bithead/replied-to/)
 *   [Engagements](https://wordpress.org/support/users/bithead/engagements/)
 *   [Favorites](https://wordpress.org/support/users/bithead/favorites/)

 Search replies:

## Forum Replies Created

Viewing 10 replies - 1 through 10 (of 10 total)

 *   Forum: [Requests and Feedback](https://wordpress.org/support/forum/requests-and-feedback/)
   
   In reply to: [plugin wish list… category control](https://wordpress.org/support/topic/plugin-wish-list-category-control/)
 *  Thread Starter [Bithead](https://wordpress.org/support/users/bithead/)
 * (@bithead)
 * [18 years, 4 months ago](https://wordpress.org/support/topic/plugin-wish-list-category-control/#post-672940)
 * JC; Yeah, I was a little disappointed myself.
    The thing worked exactly once.
   Since then, it refuses to even find anything I’m looking for. Say, all posts 
   with the words “Fred Thompson” in them, for example… I know I had at least 40
   or so. It won’t find them. In fact, no matter what string I use. No idea, and
   my fuse on the matter continues to get shorter. (Sigh)
 * Hans… did you want to say something?
 *   Forum: [Developing with WordPress](https://wordpress.org/support/forum/wp-advanced/)
   
   In reply to: [dropping phpbb tables…. OK?](https://wordpress.org/support/topic/dropping-phpbb-tables-ok/)
 *  Thread Starter [Bithead](https://wordpress.org/support/users/bithead/)
 * (@bithead)
 * [18 years, 5 months ago](https://wordpress.org/support/topic/dropping-phpbb-tables-ok/#post-657545)
 * 1: Well, yeah, that made sense, but I wasn’t totally sure if there was a hook
   there, or not, and it made sense to ask before pulling them. Thanks.
 * 2: Well, knowing the actual error is the issue, isn’t it? (Wry smile) I did manage
   to get rid of the error incidental to a cleanup I’ve been doing the last few 
   days, but I honestly don’t know what was causing it. Even the database wasn’t
   saying. (Shrug) Oh, well… thanks for the help, anyway… it’s appreciated.
 *   Forum: [Everything else WordPress](https://wordpress.org/support/forum/miscellaneous/)
   
   In reply to: [Argentina attack](https://wordpress.org/support/topic/argentina-attack/)
 *  Thread Starter [Bithead](https://wordpress.org/support/users/bithead/)
 * (@bithead)
 * [18 years, 7 months ago](https://wordpress.org/support/topic/argentina-attack/#post-619603)
 * > And [@the](https://wordpress.org/support/users/the/) OP, I’m not a GUY {{looks
   > down}} .. nope. Still a GIRL.
 * Well, you know how it is when you get married….
 * > And .. I reiterate, it is the problem of a WP PLUGIN. And to answer the question
   > where to go for help? First, to the plugin author. Some plugin devs are better
   > about support than others.
 * Maybe, but look again:
    I had no idea the problem was a plugin.
 * > I commend you for returning to this forum to report the solution.
 * Of course!
    If I complain about others not passing along what information they
   have, what kind of credibility with the complaint have if I didn’t do better 
   than what I was complaining about?
 * > Sounds to me like that post was a cut and paste job, meant for more than just
   > this forum.
 * Correct; I put the info on my blog, as well.
 *   Forum: [Everything else WordPress](https://wordpress.org/support/forum/miscellaneous/)
   
   In reply to: [Argentina attack](https://wordpress.org/support/topic/argentina-attack/)
 *  Thread Starter [Bithead](https://wordpress.org/support/users/bithead/)
 * (@bithead)
 * [18 years, 8 months ago](https://wordpress.org/support/topic/argentina-attack/#post-619569)
 * Handy and Root: Look again:
 * > And no, my anger isn’t being directed at jonimueller, but rather at the IRC
   > channel.
 * Questions?
 *   Forum: [Everything else WordPress](https://wordpress.org/support/forum/miscellaneous/)
   
   In reply to: [Argentina attack](https://wordpress.org/support/topic/argentina-attack/)
 *  Thread Starter [Bithead](https://wordpress.org/support/users/bithead/)
 * (@bithead)
 * [18 years, 8 months ago](https://wordpress.org/support/topic/argentina-attack/#post-619560)
 * Seems to me that area of responsibility is a little on the gray side, given that
   I downloaded the plug in by linking through the the word press website.
 * But more… It seems also to me, that it would be wise to be a one stop for all
   things WordPress. Your success rate could only improve with that kind of PR effort.
 * I came in here looking for WordPress expertise. Where the beep ELSE would I go
   to get such questions asked? The idea that it might have been the plugin never
   occurred to me… I admit after a few hours of my site down, I was a bit frazzled.
   But what I got while in that condition, instead of expertise from people who 
   know the package, (and presumably what people tend to add to it for the most 
   part ) what I got was Linux snobbery, and ‘it’s not our problem.” Nobody even**
   bothered** asking what wordpress plugins I was running, except the ISP. Once 
   the idea that an IIS server was involved that’s all they wanted to know. Nose
   in the air, fade to black. Didn’t even BOTHER to ask any other questions, and
   weren’t interested in the symptoms. Not exactly good PR
 * And no, my anger isn’t being directed at jonimueller, but rather at the IRC channel.
 * Enough.
    Wordpress is a fine product. Just wish the support was a little less
   tone deaf.
 *  I’m not exactly a babe in the woods on this stuff; I’ve been in end user support
   for many years. The ones who tend to do well, are the ones who don’t draw arbitrary
   support lines.
 *   Forum: [Everything else WordPress](https://wordpress.org/support/forum/miscellaneous/)
   
   In reply to: [Argentina attack](https://wordpress.org/support/topic/argentina-attack/)
 *  Thread Starter [Bithead](https://wordpress.org/support/users/bithead/)
 * (@bithead)
 * [18 years, 8 months ago](https://wordpress.org/support/topic/argentina-attack/#post-619554)
 * OK,gang, here’s the lowdown.
 * Last week, we had an attack on the core SQL database that runs BitsBlog. The 
   most obvious result of that attack was four instances of an HTML FRAME callout
   showing up showing up on the header of every page on the site.
 * ( [http://usuarios.arnet.com.ar/alvarezluque/morgan.html&#8221](http://usuarios.arnet.com.ar/alvarezluque/morgan.html&#8221);
   width=”0″ height=”0″ frameborder=”0″></iframe)
 * (Take my advice, don’t go there… in investigating the site and doing soem cross
   checking, I find there’s a bunch of real weirdos, there.)
 * Once I went through all my PHP coding by hand, I realized that the callouts were
   in none of them, and that the code must have been injected into the database.
   A database restore from my end was out of the question for several technical 
   reasons. The backup design assumed that the site would be available. Dumb, yeah,
   but there it is.
 * So, I got on with the ISP, and had them do an full wipe and restore.
 * Once that was done, and assuming that because my site was a little behind the
   WordPress current release, I then changed all my heavy passwords, and upgraded
   to the most recent version.
 * Two days later, we’re back in the soup. Logically, whatever the security hole
   was, was not directly a part of WordPress, but WHAT WAS IT? Simply having the
   ISP go to tape again, still left the Blog vulnerable.
 *  At this point, I started asking around. I went to the WordPress support forums.
   Let’s just say they’re Linux snobs, and leave it at that, shall we? I mean, I
   like Linux, too, but telling me my biggest problem is the thing is an ISS server
   isn’t helping. I was dealing with applications issues when we went the Windows
   Server route anyway.
 * Still, they had a point that the Windows environment isn’t nearly as secure, 
   so some rather pointed questions were fired at the ISP.
 *  UNlike the folks at WordPress who couldn’t get past the word “Windows”, the 
   IX folks actually investigated, and found that there was indeed a problem with
   the WordPress installation:
 * > We’ve restored your site from our backup. Also after investigation of our system
   > administration team, we’ve found that your WordPress installation is vulnerable
   > to remote file inclusion attacks. Please refer to following link for more information
   > regarding that security hole:
   >  [http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2007-05/msg00010.html](http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2007-05/msg00010.html)
   >  Please upgrade/fix your software ( wordTube plugin ) as soon as possible, 
   > and update this ticket once it’s done.
   >  Should you have any further questions, please do not hesitate to contact us
   > 24×7.
 *  Well, what do you know. An ISP actually willing to help, when the pressure is
   on. I’ve done a rebuild to the most recent versons, changed out my passwords 
   again, and blown away the YouTube plughin… it wasn’t working well anyway.
 * Kudos to IX Web hosting, for a job well done.
 * And a raspberry or three to the WordPress Support forums, and to the denizens
   of their IRC room, who were even worse. …
 * (Well, OK, the guy in the forum was apparently trying to warn me of the bias,
   but the fact remains the help forum was anything but… even there, he decided 
   it wasn’t a wordpress issue.)
 *   Forum: [Installing WordPress](https://wordpress.org/support/forum/installation/)
   
   In reply to: [Importing from Blogger](https://wordpress.org/support/topic/importing-from-blogger-1-3/)
 *  Thread Starter [Bithead](https://wordpress.org/support/users/bithead/)
 * (@bithead)
 * [19 years, 5 months ago](https://wordpress.org/support/topic/importing-from-blogger-1-3/#post-483561)
 * OK, part one is solved… the imported finally allowed me to reset it. It’s working
   as well as it was, again.
 * But I still can’t get through the whole pile of posts.
 * Anyone know how I can do a date-based detele of posts in Blogger, so I can make
   the inhaled amount smaller?
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [adding a blockquote button to the author posting window?](https://wordpress.org/support/topic/adding-a-blockquote-button-to-the-author-posting-window/)
 *  Thread Starter [Bithead](https://wordpress.org/support/users/bithead/)
 * (@bithead)
 * [19 years, 5 months ago](https://wordpress.org/support/topic/adding-a-blockquote-button-to-the-author-posting-window/#post-483233)
 * Sheesh… that’s two I owe you. I thought that was, as the script says, just an
   indent.
 *   Forum: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
   
   In reply to: [WordPress newbie in a problem](https://wordpress.org/support/topic/wordpress-newbie-in-a-problem/)
 *  Thread Starter [Bithead](https://wordpress.org/support/users/bithead/)
 * (@bithead)
 * [19 years, 5 months ago](https://wordpress.org/support/topic/wordpress-newbie-in-a-problem/#post-482707)
 * Yep. That was it.
    Many, many thanks.
 *   Forum: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
   
   In reply to: [WordPress newbie in a problem](https://wordpress.org/support/topic/wordpress-newbie-in-a-problem/)
 *  Thread Starter [Bithead](https://wordpress.org/support/users/bithead/)
 * (@bithead)
 * [19 years, 5 months ago](https://wordpress.org/support/topic/wordpress-newbie-in-a-problem/#post-482706)
 * Oh?
    Hmmm.
 * OK, I’ll look at that. Thanks

Viewing 10 replies - 1 through 10 (of 10 total)